Social EngineeringPhishingTargetedPIIIDENTITY_BASICLowContained
Reading Cooperative Bank
bd_03550ed043b521c4 · schema v1 · pii pii-v1
Full breach record for Reading Cooperative Bank →Reading Cooperative Bank notified Vermont AG on 2025-02-24 of a security incident caused by an employee clicking a phishing email. The bank engaged third-party experts and implemented additional safeguards. PII of customers may have been impacted. The bank is offering 24 months of Experian IdentityWorks. No specific count of affected individuals was disclosed.
Vermont clock✓ VT AG ≤14 bday≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_02dea8362f280694Maryland State AGfiled 2025-02-24Verified
- bd_286bccc460c3cdadNew Hampshire State AGfiled 2025-02-24Verified
- bd_b84836cd62e897a2Maine State AGfiled 2025-02-24Candidate
- bd_c359101a4dbd2ec0Indiana State AGfiled 2025-02-24Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-02-24-reading-cooperative-bank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 24, 2025
- Raw hash
- 5832df9e3d7ed1e3890275ab438620069eb3f1911724764c8f9df9772dad9a5a
Reporting entity
- Name
- Reading Cooperative Banknorm: reading cooperative bank
- Domain
- readingcoop.com
Victim entity
- Name
- Reading Cooperative Banknorm: reading cooperative bank
- Domain
- readingcoop.com
Incident
- Discovered
- Feb 24, 2025
- Materiality determined
- —
- Notification sent
- Feb 24, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.